combofix...
"Owner" - 07-04-14 21:28:08 Service Pack 2
ComboFix 07-04-05.Rev3 - Running from: "C:\Documents and Settings\Owner\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\{3CC1D~1\UnInstall.exe
C:\lswmv.ini
C:\WINDOWS\system32\sstqp.dll
C:\Program Files\Common Files\Uninstall Information
C:\Program Files\Common Files\{3CC1D~1
C:\Program Files\Common Files\{5CC1D~1
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CMDSERVICE
-------\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((((((((( Files Created from 2007-03-14 to 2007-04-14 ))))))))))))))))))))))))))))))))))
2007-04-14 20:47 <DIR> d-------- C:\VundoFix Backups
2007-04-14 15:07 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-04-14 02:07 3,310 --a------ C:\WINDOWS\system32\tmp.reg
2007-04-13 21:19 26,694 --a------ C:\WINDOWS\system32\xxyyayx.dll
2007-04-13 21:09 26,694 --a------ C:\WINDOWS\system32\awtqnnm.dll
2007-04-13 20:59 26,694 --a------ C:\WINDOWS\system32\ljjklkj.dll
2007-04-13 20:49 26,694 --a------ C:\WINDOWS\system32\ddccbyx.dll
2007-04-13 20:39 26,694 --a------ C:\WINDOWS\system32\xxyyywt.dll
2007-04-13 20:29 26,694 --a------ C:\WINDOWS\system32\efccbcy.dll
2007-04-13 20:19 26,694 --a------ C:\WINDOWS\system32\cbxuutt.dll
2007-04-13 20:09 26,694 --a------ C:\WINDOWS\system32\pmnoomj.dll
2007-04-13 19:59 26,694 --a------ C:\WINDOWS\system32\pmnolif.dll
2007-04-13 19:49 26,694 --a------ C:\WINDOWS\system32\byxxyvv.dll
2007-04-13 19:39 26,694 --a------ C:\WINDOWS\system32\ddcbcda.dll
2007-04-13 19:29 26,694 --a------ C:\WINDOWS\system32\tuvsstq.dll
2007-04-13 19:19 26,694 --a------ C:\WINDOWS\system32\jkkhghg.dll
2007-04-13 19:09 26,694 --a------ C:\WINDOWS\system32\ljjgffg.dll
2007-04-13 18:44 26,694 --a------ C:\WINDOWS\system32\ddcbbba.dll
2007-04-13 18:29 26,694 --a------ C:\WINDOWS\system32\rqrqrpn.dll
2007-04-13 18:19 26,694 --a------ C:\WINDOWS\system32\nnnonmk.dll
2007-04-13 18:09 26,694 --a------ C:\WINDOWS\system32\nnnopoo.dll
2007-04-13 17:59 26,694 --a------ C:\WINDOWS\system32\xxywwuu.dll
2007-04-13 17:49 26,694 --a------ C:\WINDOWS\system32\ddcbxus.dll
2007-04-13 17:39 26,694 --a------ C:\WINDOWS\system32\vtuurqr.dll
2007-04-13 17:29 26,694 --a------ C:\WINDOWS\system32\fcccyyx.dll
2007-04-13 17:19 26,694 --a------ C:\WINDOWS\system32\pmnnkhg.dll
2007-04-13 17:09 26,694 --a------ C:\WINDOWS\system32\tuvusrq.dll
2007-04-13 16:59 26,694 --a------ C:\WINDOWS\system32\vtutrro.dll
2007-04-13 16:49 26,694 --a------ C:\WINDOWS\system32\qomnkhg.dll
2007-04-13 16:39 26,694 --a------ C:\WINDOWS\system32\wvuvwts.dll
2007-04-13 16:29 26,694 --a------ C:\WINDOWS\system32\mljhigf.dll
2007-04-13 16:19 26,694 --a------ C:\WINDOWS\system32\awtsqqn.dll
2007-04-13 16:09 26,694 --a------ C:\WINDOWS\system32\awtuuvu.dll
2007-04-13 15:59 26,694 --a------ C:\WINDOWS\system32\hgghfed.dll
2007-04-13 15:49 26,694 --a------ C:\WINDOWS\system32\byxxxvw.dll
2007-04-13 15:39 26,694 --a------ C:\WINDOWS\system32\iifeefe.dll
2007-04-13 15:29 26,694 --a------ C:\WINDOWS\system32\byxyvts.dll
2007-04-13 15:19 26,694 --a------ C:\WINDOWS\system32\byxuuvs.dll
2007-04-13 15:09 26,694 --a------ C:\WINDOWS\system32\khfdbay.dll
2007-04-13 14:59 26,694 --a------ C:\WINDOWS\system32\nnnolmj.dll
2007-04-13 14:49 26,694 --a------ C:\WINDOWS\system32\ssqpqol.dll
2007-04-13 14:39 26,694 --a------ C:\WINDOWS\system32\ssqnoli.dll
2007-04-13 14:29 26,694 --a------ C:\WINDOWS\system32\hggfcba.dll
2007-04-13 14:19 26,694 --a------ C:\WINDOWS\system32\ssqollk.dll
2007-04-13 14:09 26,694 --a------ C:\WINDOWS\system32\ljjgfcb.dll
2007-04-13 13:59 26,694 --a------ C:\WINDOWS\system32\efcbaba.dll
2007-04-13 13:49 26,694 --a------ C:\WINDOWS\system32\nnnmnkj.dll
2007-04-13 13:39 26,694 --a------ C:\WINDOWS\system32\jkklmmk.dll
2007-04-13 13:29 26,694 --a------ C:\WINDOWS\system32\tuvsrpn.dll
2007-04-13 13:19 26,694 --a------ C:\WINDOWS\system32\tuvwwtr.dll
2007-04-13 13:09 26,694 --a------ C:\WINDOWS\system32\yayabyw.dll
2007-04-13 12:59 26,694 --a------ C:\WINDOWS\system32\byxuvsr.dll
2007-04-13 12:49 26,694 --a------ C:\WINDOWS\system32\qomkiff.dll
2007-04-13 12:39 26,694 --a------ C:\WINDOWS\system32\iifffed.dll
2007-04-13 12:29 26,694 --a------ C:\WINDOWS\system32\gebcaxv.dll
2007-04-13 12:19 26,694 --a------ C:\WINDOWS\system32\yaywwur.dll
2007-04-13 12:09 26,694 --a------ C:\WINDOWS\system32\qomkife.dll
2007-04-13 11:59 26,694 --a------ C:\WINDOWS\system32\rqrrspn.dll
2007-04-13 11:49 26,694 --a------ C:\WINDOWS\system32\khfddee.dll
2007-04-13 11:39 26,694 --a------ C:\WINDOWS\system32\iifgghe.dll
2007-04-13 11:29 26,694 --a------ C:\WINDOWS\system32\awtsrsr.dll
2007-04-13 11:19 26,694 --a------ C:\WINDOWS\system32\xxyayvt.dll
2007-04-13 11:09 26,694 --a------ C:\WINDOWS\system32\efccbyx.dll
2007-04-13 10:59 26,694 --a------ C:\WINDOWS\system32\qomkhfd.dll
2007-04-13 10:49 26,694 --a------ C:\WINDOWS\system32\iifccay.dll
2007-04-13 10:39 26,694 --a------ C:\WINDOWS\system32\mljiife.dll
2007-04-13 10:29 26,694 --a------ C:\WINDOWS\system32\yayabxv.dll
2007-04-13 10:19 26,694 --a------ C:\WINDOWS\system32\cbxxwuv.dll
2007-04-13 10:09 26,694 --a------ C:\WINDOWS\system32\pmnkkhe.dll
2007-04-13 09:59 26,694 --a------ C:\WINDOWS\system32\qomjgfc.dll
2007-04-13 09:47 26,694 --a------ C:\WINDOWS\system32\ssqpqqr.dll
2007-04-13 09:37 26,694 --a------ C:\WINDOWS\system32\khfcdby.dll
2007-04-13 09:27 26,694 --a------ C:\WINDOWS\system32\mljiggg.dll
2007-04-13 09:17 26,694 --a------ C:\WINDOWS\system32\mljgddd.dll
2007-04-13 09:08 26,694 --a------ C:\WINDOWS\system32\qomjkkk.dll
2007-04-13 00:26 800,503 ---hs---- C:\WINDOWS\system32\ppqss.bak1
2007-04-13 00:22 26,694 --a------ C:\WINDOWS\system32\ssqrqqr.dll
2007-04-13 00:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-04-12 01:17 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-11 23:45 <DIR> d-------- C:\Program Files\CCleaner
2007-04-11 20:01 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Uniblue
2007-04-11 07:54 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Opera
2007-04-11 01:30 26,694 --a------ C:\WINDOWS\system32\fccbxwv.dll
2007-04-11 01:21 26,694 --a------ C:\WINDOWS\system32\fccbaxy.dll
2007-04-11 00:54 26,694 --a------ C:\WINDOWS\system32\byxxuvw.dll
2007-04-11 00:44 26,694 --a------ C:\WINDOWS\system32\khfccyv.dll
2007-04-11 00:34 26,694 --a------ C:\WINDOWS\system32\nnnmmjk.dll
2007-04-11 00:24 26,694 --a------ C:\WINDOWS\system32\xxyvwur.dll
2007-04-11 00:09 26,694 --a------ C:\WINDOWS\system32\gebbyxw.dll
2007-04-10 23:59 26,694 --a------ C:\WINDOWS\system32\cbxywvw.dll
2007-04-10 23:49 26,694 --a------ C:\WINDOWS\system32\cbxxywt.dll
2007-04-10 23:39 26,694 --a------ C:\WINDOWS\system32\ljjigfe.dll
2007-04-10 23:32 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-04-10 23:31 <DIR> d--hs---- C:\WINDOWS\Q2hlcnlsIE1hc3NleQ
2007-04-10 23:29 26,694 --a------ C:\WINDOWS\system32\awtqonm.dll
2007-04-10 23:19 26,694 --a------ C:\WINDOWS\system32\tuvuvwu.dll
2007-04-10 20:30 26,694 --a------ C:\WINDOWS\system32\xxyayya.dll
2007-04-10 20:23 26,694 --a------ C:\WINDOWS\system32\gebayxy.dll
2007-04-10 20:13 26,694 --a------ C:\WINDOWS\system32\awtsqqp.dll
2007-04-10 20:04 26,694 --a------ C:\WINDOWS\system32\wvuvwxw.dll
2007-04-10 19:20 26,694 --a------ C:\WINDOWS\system32\fccayyx.dll
2007-04-10 19:05 26,694 --a------ C:\WINDOWS\system32\yayxvwv.dll
2007-04-10 18:55 26,694 --a------ C:\WINDOWS\system32\cbxyaxx.dll
2007-04-10 18:45 26,694 --a------ C:\WINDOWS\system32\qomlife.dll
2007-04-10 08:55 26,694 --a------ C:\WINDOWS\system32\wvurron.dll
2007-04-10 08:45 26,694 --a------ C:\WINDOWS\system32\byxwwvv.dll
2007-04-10 08:35 26,694 --a------ C:\WINDOWS\system32\cbxwwwt.dll
2007-04-10 08:25 26,694 --a------ C:\WINDOWS\system32\ssqoopo.dll
2007-04-10 08:15 26,694 --a------ C:\WINDOWS\system32\tuvtspm.dll
2007-04-10 08:00 26,694 --a------ C:\WINDOWS\system32\cbxxwvw.dll
2007-04-10 07:50 26,694 --a------ C:\WINDOWS\system32\ddccaxx.dll
2007-04-10 07:35 26,694 --a------ C:\WINDOWS\system32\vtusrqn.dll
2007-04-10 03:46 26,694 --a------ C:\WINDOWS\system32\byxvvtt.dll
2007-04-10 03:36 26,694 --a------ C:\WINDOWS\system32\opnonll.dll
2007-04-10 03:21 26,694 --a------ C:\WINDOWS\system32\rqrppqp.dll
2007-04-10 03:11 26,694 --a------ C:\WINDOWS\system32\efcyxxu.dll
2007-04-10 02:56 26,694 --a------ C:\WINDOWS\system32\fccyaxw.dll
2007-04-10 02:46 26,694 --a------ C:\WINDOWS\system32\cbxwtqr.dll
2007-04-10 02:36 26,694 --a------ C:\WINDOWS\system32\ssqrqqp.dll
2007-04-10 02:26 26,694 --a------ C:\WINDOWS\system32\ddcbbby.dll
2007-04-10 02:06 26,694 --a------ C:\WINDOWS\system32\ssqnoml.dll
2007-04-10 01:46 26,694 --a------ C:\WINDOWS\system32\pmnmkij.dll
2007-04-10 01:36 26,694 --a------ C:\WINDOWS\system32\nnnnkjk.dll
2007-04-10 01:21 26,694 --a------ C:\WINDOWS\system32\opnkjif.dll
2007-04-10 01:11 26,694 --a------ C:\WINDOWS\system32\tuvtstt.dll
2007-04-10 01:01 26,694 --a------ C:\WINDOWS\system32\cbxusrs.dll
2007-04-10 00:51 26,694 --a------ C:\WINDOWS\system32\wvusqro.dll
2007-04-10 00:31 26,694 --a------ C:\WINDOWS\system32\awtrqpo.dll
2007-04-10 00:21 26,694 --a------ C:\WINDOWS\system32\khfgheb.dll
2007-04-10 00:06 26,694 --a------ C:\WINDOWS\system32\khfefgf.dll
2007-04-09 23:56 26,694 --a------ C:\WINDOWS\system32\yayvuvu.dll
2007-04-09 23:46 26,694 --a------ C:\WINDOWS\system32\yayawur.dll
2007-04-09 23:36 26,694 --a------ C:\WINDOWS\system32\qommnkk.dll
2007-04-09 23:21 26,694 --a------ C:\WINDOWS\system32\wvusqpp.dll
2007-04-09 23:11 26,694 --a------ C:\WINDOWS\system32\pmnlifc.dll
2007-04-09 23:01 26,694 --a------ C:\WINDOWS\system32\ljjifdc.dll
2007-04-09 22:51 26,694 --a------ C:\WINDOWS\system32\fccdbbx.dll
2007-04-09 22:41 26,694 --a------ C:\WINDOWS\system32\opnkigh.dll
2007-04-09 22:31 26,694 --a------ C:\WINDOWS\system32\urqqnol.dll
2007-04-09 22:21 26,694 --a------ C:\WINDOWS\system32\tuvwuro.dll
2007-04-09 22:11 26,694 --a------ C:\WINDOWS\system32\nnnnlih.dll
2007-04-09 21:57 26,694 --a------ C:\WINDOWS\system32\ssqomji.dll
2007-04-09 21:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
2007-04-09 21:46 26,694 --a------ C:\WINDOWS\system32\byxwwvw.dll
2007-04-09 21:32 26,694 --a------ C:\WINDOWS\system32\rqroolk.dll
2007-04-09 21:27 801,556 ---hs---- C:\WINDOWS\system32\ppqss.ini2
2007-04-09 21:13 26,694 --a------ C:\WINDOWS\system32\rqrsspq.dll
2007-04-09 21:03 26,694 --a------ C:\WINDOWS\system32\tuvtuvt.dll
2007-04-09 20:53 26,694 --a------ C:\WINDOWS\system32\nnnmkij.dll
2007-04-09 20:43 26,694 --a------ C:\WINDOWS\system32\urqqool.dll
2007-04-09 20:33 26,694 --a------ C:\WINDOWS\system32\xxyaywx.dll
2007-04-09 20:23 26,694 --a------ C:\WINDOWS\system32\wvuttrp.dll
2007-04-09 20:13 26,694 --a------ C:\WINDOWS\system32\opnlkig.dll
2007-04-09 20:03 26,694 --a------ C:\WINDOWS\system32\urqpmji.dll
2007-04-09 19:53 26,694 --a------ C:\WINDOWS\system32\opnljkj.dll
2007-04-09 19:43 26,694 --a------ C:\WINDOWS\system32\vtuutus.dll
2007-04-09 19:39 280,676 ---hs---- C:\WINDOWS\system32\sstqn.dll
2007-04-09 19:34 26,694 --a------ C:\WINDOWS\system32\yayyawt.dll
2007-04-09 19:27 26,694 --a------ C:\WINDOWS\system32\qomnnnk.dll
2007-04-09 19:27 26,694 --a------ C:\WINDOWS\system32\qomnlll.dll
2007-04-09 19:27 26,694 --a------ C:\WINDOWS\system32\pmnkigd.dll
2007-04-09 19:27 26,694 --a------ C:\WINDOWS\system32\awtqppo.dll
2007-04-09 19:26 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-03-23 15:11 127,034 -r------- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2007-03-16 23:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-03-16 23:36 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-03-16 23:36 <DIR> d-------- C:\Program Files\Common Files\Kodak
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
2007-04-14 21:25 -------- d-------- C:\Program Files\hijack this
2007-04-14 18:32 -------- d-------- C:\Program Files\msn messenger
2007-04-12 00:15 -------- d-------- C:\Program Files\ewido anti-malware
2007-04-11 23:46 -------- d-------- C:\Program Files\yahoo!
2007-04-09 23:31 -------- d-------- C:\Program Files\windows live safety center
2007-03-17 07:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-16 23:37 -------- d-------- C:\Program Files\kodak
2007-03-08 09:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 09:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 09:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 07:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 18:48 -------- d-------- C:\Program Files\java
2007-02-05 14:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-01-19 12:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run]
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"IncrediMail"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe /c"
"LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessen ger.exe"
"LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.ex e"
"Uniblue Registry Booster2"="C:\\Program Files\\Uniblue\\RegistryBooster2\\RegistryBooster. exe /S"
"IpWins"="C:\\Program Files\\Ipwindows\\ipwins.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run]
"StorageGuard"="\"C:\\Program Files\\VERITAS Software\\Update Manager\\sgtray.exe\" /r"
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"hpsysdrv"="c:\\windows\\system\\hpsysdrv.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.ex e"
"PS2"="C:\\WINDOWS\\system32\\ps2.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72, 6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b ,00
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc. exe /STARTUP"
"PrintDrive"="rundll32.exe \"C:\\WINDOWS\\system32\\nencjthj.dll\",setvm"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\runonce]
"SRUUninstall"="\"C:\\WINDOWS\\System32\\msiexec.e xe\" /x {6AF90EF6-F7F9-466C-99F4-1774826FBB40} /qn REBOOT=ReallySuppress"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Norton Antivirus Startup Entry.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Norton Antivirus Startup Entry.lnk"
"backup"="C:\\WINDOWS\\pss\\Norton Antivirus Startup Entry.lnkStartup"
"location"="Startup"
"item"="Norton Antivirus Startup Entry"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\windows auto update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="apitrap.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{970D022E-A884-4D2A-BB4A-EBC22D2FEBD2}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"NoAdminPage"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"ClearRecentDocsOnExit"=hex:01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://www.perfectphotos.ca/albums/I...ides_1_202.jpg
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source REG_SZ C:\wedding stuff\wedding_desktop.html
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomnnnk
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnph ost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\EasyShare Registration Task.job
C:\WINDOWS\tasks\Symantec NetDetect.job
************************************************** ******************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
************************************************** ******************
Completion time: 07-04-14 21:40:02
C:\ComboFix-quarantined-files.txt ... 07-04-14 21:40



